CVE-2025-1128

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Feb 25, 2025
Updated: Feb 28, 2025
CWE ID 434

Summary

CVE-2025-1128 is a vulnerability affecting the Everest Forms plugin for WordPress. This issue, present in all versions up to 3.0.9.4, enables unauthenticated attackers to upload, read, and delete arbitrary files on the affected site's server. The 'format' method in the EVF_Form_Fields_Upload class lacks proper file type and path validation, making it exploitable. The potential consequences include remote code execution, sensitive information disclosure, or a complete site takeover.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share